ESQL/C program called from SPL with SYSTEM command
Posted in 2018
Hi Informixers,
please bear with me if the following sounds a little confusing. I am
thoroughly confused myself.
We're running IDS 12.10.FC8W1WE on SLES 12 SP1. The system is configured to
authenticate users via local files (/etc/passwd) and sssd against an Active
Directory domain.
ESQL/C programs run fine when called from the command line and via crond.
However, the same programs experience delays starting up when called in a
stored procedure via the SYSTEM command.
Via strace, I found out that ESQL/C programs read /proc/self/loginuid to find
out the UID they are running under. When called from SPL, this yields
"4294967295", which is equivalent to "-1". Following the settings in
nsswitch.conf, first the local passwd file is queried and then AD via sssd,
with both queries being unsuccessful, of course. The AD query with UID
"4294967295" causes the delay of 6-8 seconds on average, but sometimes up to
one minute.
After that delay, getuid() is called which results in the correct UID of the
user invoking the stored procedure, and the program continues successfully.
I assume this might be a PAM issue, since there is a PAM module
pam_loginuid.so that is invoked e.g. by crond to set the correct loginuid for
a program called via the cron mechanism. Any idea how to make IDS use
pam_loginuid.so when calling a program via SPL?
This is my sqlhosts:
xxserver onipcshm anaxxx.srv.mxx.xxx.de opserver_shm
xxserver_tcp onsoctcp anaxxx.srv.mxx.xxx.de sqlexec
s=4,pam_serv=(pam_informix),pamauth=(password)
xxserver_classic onsoctcp anaxxx.srv.mxx.xxx.de 22222
And the pam_informix file in /etc/pam.d:
auth sufficient pam_rhosts.so
auth sufficient pam_unix.so
auth sufficient pam_sss.so use_first_pass
account required pam_unix.so
Please note that the described behavior occurs no matter which connection the
invoking user is using; the ESQL/C program will always use the local shared
memory connection when called via SPL, but the DB connection is established
after the described delay.
BTW: getpwnam() works with both /etc/passwd and sssd, so the explicit PAM
configuration is most likely not even necessary.
Regards, Richard